Chrome OS Remote Access policy was modified in Google Workspace
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Google Workspace
ATT&CK Tactic
Lateral Movement (TA0008), Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Remote Services (T1021)
Severity
Informational
Description
A user modified Chrome OS Remote Access configuration in Google Workspace.
Attacker's Goals
Adversaries may modify remote access settings to maintain persistent access and bypass security controls.
Investigative actions
Verify if the configuration change was authorized.
Investigate the source IP address and account involved for malicious activity.
Follow further actions performed by the account and Remote Access connections performed.
Variations
Was this helpful?
